Risk

What is “RiskTool.Win32.Miner.avq”?

Malware Removal

The RiskTool.Win32.Miner.avq is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What RiskTool.Win32.Miner.avq virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Starts servers listening on :0, 0.0.0.0:9333
  • Enumerates running processes
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets

How to determine RiskTool.Win32.Miner.avq?


File Info:

name: 07317449D716D22A76AD.mlw
path: /opt/CAPEv2/storage/binaries/8463e3dcf8b66a55d4f12c04be64b144483d09102a92fa1dd2fe3ce2c3ce554e
crc32: 90F90F78
md5: 07317449d716d22a76ad230ea92051fd
sha1: 8d2b653dbfcde822ce7c4ce535d2baed200e79d8
sha256: 8463e3dcf8b66a55d4f12c04be64b144483d09102a92fa1dd2fe3ce2c3ce554e
sha512: 88eda6062f3c8f831bba968acc1117000d24b7d3b005e58f7d3a30e1ab16e636749cf090bbaa683ab21948d866178d59eeddb6c55ff02b91f966f53366e0357d
ssdeep: 98304:HOGhYpIQPeJpJgXCcibxRZFG5nhVA7WT61EAK2V+Z6iauxZppD+y+oQku6CURDXp:uOYpIQP+JgXCcibxonQl1EAK2wZ6huxL
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T136561908E78780F5ED5309B06507FBBF8A216A31D020CCA6F684DF5AEA73DD6661D316
sha3_384: ce8e55d5ef4caf3f3b3b095e434b9c5ac7becf63846627b199a6f12e588d1a8bb84f0f3056a945958ffb7a5a9577ac5e
ep_bytes: 83ec0cc705e8f89d0000000000e8ee71
timestamp: 2011-01-30 00:00:00

Version Info:

0: [No Data]

RiskTool.Win32.Miner.avq also known as:

LionicRiskware.Win32.Miner.1!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.07317449d716d22a
McAfeeArtemis!07317449D716
CylanceUnsafe
SangforCoinMiner.Win32.Miner.avq
AlibabaRiskWare:Win32/Miners.fa25d4e1
ESET-NOD32a variant of Win32/CoinMiner.BJ potentially unwanted
Kasperskynot-a-virus:RiskTool.Win32.Miner.avq
NANO-AntivirusRiskware.Win32.Miner.fobyon
SophosBitcoin Miner (PUA)
ZillyaTool.Miner.Win32.439
SentinelOneStatic AI – Suspicious PE
JiangminRiskTool.Miner.bs
ZoneAlarmnot-a-virus:RiskTool.Win32.Miner.avq
MalwarebytesGeneric.Malware/Suspicious
RisingPUA.CoinMiner!8.4639 (TFE:dGZlOgXXs/SueLzJ9A)
YandexTrojan.GenAsa!ebZc+OeHK48
IkarusPUA.CoinMiner
FortinetRiskware/CoinMiner

How to remove RiskTool.Win32.Miner.avq?

RiskTool.Win32.Miner.avq removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment